WorksheetsPre-test CEH v13
Total questions: 15
Worksheet time: 8mins
A professional attacker exploits discovered vulnerabilities to enter a network and escalate privileges. Which phase of hacking is this?
Maintaining access
Scanning
Gaining access
Reconnaissance
An attacker scans domains, subdomains, IP ranges, DNS records, and Whois. What type of information is primarily extracted?
Physical security information
Policy information
Network information
Company product information
Which search engine tool lets an attacker use an image to query and track original sources and details of photos, profiles, and memes?
Mention
Intelius
Sublist3r
TinEye
Which command allows an attacker with administrator privileges to hide any file or folder in a Windows system?
attrib +h +s +r
net user
net user
mkdir .HiddenMaliciousFiles
Which technique involves leveraging features of regularly used applications such as PDFs or Windows shortcut files (.lnk) to execute malicious commands?
Native applications
Malicious websites
Exploiting non-malicious files
Memory code injection
Which Windows Service Manager (SrvMan) command is used to install and start a legacy driver with a single call?
srvman.exe add
srvman.exe delete
srvman.exe restart
srvman.exe run
Identify the malware analysis platform used to scan files, URLs, endpoints, and memory dumps, helping extract strings and identify their use in other files.
Network Spoofer
Intezer
cSploit
xHelper
Which protocol allows a user’s workstation to access mail from a mailbox server and send mail from the workstation to the mailbox server via SMTP?
FTP
SMTP
HTTP
POP
Which of the following is a generic exploit designed to perform advanced attacks against human elements to compromise a target to offer sensitive information?
Wireshark
NetScanTools Pro
Cain and Abel
Social-Engineer Toolkit (SET)
In which of the following attacks does an attacker use a combination of volumetric, protocol, and application-layer attacks to take down a target system or service?
HTTP GET/POST attack
Slowloris attack
Peer-to-peer attack
Multi-vector attack
In which of the following session hijacking phases does an attacker break the connection to a victim's machine with knowledge of the next sequence number (NSN)?
Session ID prediction
Session desynchronization
Command injection
Monitor
Which attack abuses data compression in protocols like SSL/TLS, SPDY, and HTTPS to decrypt secret session cookies and hijack sessions?
CRIME attack
Proxy servers
Session donation attack
Forbidden attack
Which technique manipulates the TCP/IP stack to slow worms and backdoors?
Layer 4 tar pits
Layer 2 tar pits
Layer 7 tar pits
Honeyd honeypot
An attacker wants to perform a session hijacking attack. What tool should he use to achieve his objective?
Burp Suite
Netcraft
Nessus
Hydra
One of the following is a clickjacking technique in which an attacker creates an iframe of 1 × 1 pixels containing malicious content placed secretly under the mouse cursor. When the user clicks on this cursor, it will be registered on a malicious page. Which is this clickjacking technique?
Complete transparent overlay
Click event dropping
Hidden overlay
Rapid content replacement
